Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Jiri Belka

Researcher fromRed Hat
#20266of 53,633
12.7Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2017-8958
5.5
2017-08-22
Ovirt · Ovirt Engine · CVE-2016-6310
**Name of the Vulnerable Software and Affected Versions** oVirt Engine versions prior to 4.0 **Description** The issue concerns the disclosure of sensitive information, specifically the ENGINE HTTPS PKI TRUST STORE PASSWORD, which is logged in the /var/log/ovirt-engine/engine.log file. This affects oVirt Engine in RHEV before version 4.0. **Recommendations** For versions prior to 4.0, update to version 4.0 or later to resolve the issue.
PT-2013-3577
7.2
2013-08-28
Red Hat · Rhev-Guest-Tools-Iso · CVE-2013-2176
**Name of the Vulnerable Software and Affected Versions** Red Hat Enterprise Virtualization Application Provisioning Tool (RHEV-APT) version 3.2 **Description** The issue allows local users to gain privileges via a Trojan horse application due to an unquoted Windows search path vulnerability in the rhev-guest-tools-iso package. **Recommendations** For version 3.2, update the rhev-guest-tools-iso package to a version that quotes the Windows search path to prevent exploitation.